2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-18676HIGH7.5An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffe...
CVE-2019-18580CRITICAL10Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerabil...
CVE-2019-18456MEDIUM5.3An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by E...
CVE-2019-18455HIGH7.5An issue was discovered in GitLab Community and Enterprise Edition 11 through 12.4 when building Nested GraphQL queries....
CVE-2019-18454MEDIUM6.1An issue was discovered in GitLab Community and Enterprise Edition 10.5 through 12.4 in link validation for RDoc wiki pa...
CVE-2019-18453MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition 11.6 through 12.4 in the add comments via email featu...
CVE-2019-18452MEDIUM5.3An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public pr...
CVE-2019-18451MEDIUM6.1An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering...
CVE-2019-18450MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the Project labels feature. It has Ins...
CVE-2019-18449MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the autocomplete feature. It has Insec...
CVE-2019-18448MEDIUM6.5An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Incorrect Access Control.
CVE-2019-18447MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Insecure Permissions.
CVE-2019-18446MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4. It has Insecure Permissions (issue...
CVE-2019-15845MEDIUM6.5Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 mishandles path checking within File.fnmatch functions.
CVE-2019-14449MEDIUM5.4An issue was discovered in Cloudera Manager 5.x before 5.16.2, 6.0.x before 6.0.2, and 6.1.x before 6.1.1. Malicious imp...
CVE-2019-12526CRITICAL9.8An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. W...
CVE-2019-12523CRITICAL9.1An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTT...
CVE-2019-7319HIGH8.3An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBa...
CVE-2019-6477HIGH7.5With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query receiv...
CVE-2019-4387HIGH8.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.2.0 is vulnerable to SQL injection. A remote attacker c...
CVE-2019-19307CRITICAL9.8An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infin...
CVE-2019-19129MEDIUM6.1Afterlogic WebMail Pro 8.3.11, and WebMail in Afterlogic Aurora 8.3.11, allows Remote Stored XSS via an attachment name.
CVE-2019-18459MEDIUM5.3An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. I...
CVE-2019-18458LOW2.7An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 2 of...
CVE-2019-18457HIGH8.8An issue was discovered in GitLab Community and Enterprise Edition 11.8 through 12.4 when handling Security tokens.. It ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now